-
Notifications
You must be signed in to change notification settings - Fork 0
CVE-2022-3517 @ Npm-minimatch-3.0.4 #8
Description
Vulnerable Package issue exists @ Npm-minimatch-3.0.4 in branch main
A vulnerability was found in the minimatch package versions prior to 3.0.5. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the "braceExpand" function with specific arguments, resulting in a Denial of Service.
Namespace: yangricardo
Repository: nextjs-tailwind-reacthook-form-ant-design-template
Repository Url: https://github.com/yangricardo/nextjs-tailwind-reacthook-form-ant-design-template
CxAST-Project: yangricardo/nextjs-tailwind-reacthook-form-ant-design-template
CxAST platform scan: 1c12eb90-4f8a-4eb7-a810-acf7fa5369de
Branch: main
Application: nextjs-tailwind-reacthook-form-ant-design-template
Severity: HIGH
State: NOT_IGNORED
Status: RECURRENT
CWE: CWE-400
Additional Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: NONE
Availability impact: HIGH
Remediation Upgrade Recommendation: 3.0.5